Junglewise Threat Intelligence

CVE-2026-35624: OpenClaw Nextcloud Talk authorization bypass via room name collision

CVE-2026-35624 · Severity: medium · CVSS 4.2 · Published 2026-03-26

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a library used for Nextcloud Talk integrations, contains a vulnerability where it incorrectly identifies chat rooms by their names instead of unique internal IDs. This could allow an attacker to bypass access controls by creating a room with a name that matches a restricted one, potentially leading to unauthorized access to private communications. Organizations using this library should update to the latest version to ensure room policies are correctly enforced.

Technical details

An authorization bypass vulnerability exists in the Nextcloud Talk extension of OpenClaw due to the use of non-unique room display names for policy enforcement. The root cause is located in `extensions/nextcloud-talk/src/policy.ts`, where authorization checks were keyed on room names rather than stable, unique room tokens. A remote attacker with low privileges could exploit this by creating a room with a name that collides with an existing allowlisted room, leading to policy confusion and unauthorized access. The vulnerability is fixed in version 2026.3.22 by ensuring room identity is resolved using `roomToken` in both inbound processing and policy enforcement.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-24: patched: Fix shipped in v2026.3.22
  • 2026-03-26: advisory: GitHub Advisory published

References

Related threats